Skip to main content
—
Framework library
Framework module · nist-800-53-rev5

NIST SP 800-53

NIST's federal security and privacy control catalog, used directly or tailored by programs such as FedRAMP and CMS ARC-AMPE. CMMC Level 2 instead uses NIST SP 800-171 requirements.

Rev. 5, Release 5.2.0 · NIST Computer Security Resource Center · published 2025-08-27

Standing today
Directory entry

00Answer

from the registry record
What is NIST SP 800-53?
NIST's federal security and privacy control catalog, used directly or tailored by programs such as FedRAMP and CMS ARC-AMPE. CMMC Level 2 instead uses NIST SP 800-171 requirements.
Who does NIST SP 800-53 apply to?
NIST SP 800-53 applies to federal, critical infrastructure, technology, US, global, per NIST Computer Security Resource Center.
What is the current version of NIST SP 800-53?
The current edition is Rev. 5, Release 5.2.0, issued by NIST Computer Security Resource Center and published 2025-08-27. Source: https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final.
What does an assessment under NIST SP 800-53 require?
1,196 control units are on record (1,196 OSCAL catalog entries in NIST SP 800-53 Rev. 5, Release 5.2.0: 324 base controls and 872 enhancements; 1,014 active and 182 withdrawn. This is catalog scope, not tenant evidence coverage or onboarding readiness.), organized into 20 control families: AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

NIST SP 800-53 has a source-backed catalog for public inspection. No tenant onboarding blueprint or executable evidence method is activated.

No control catalog has been ingested for this regime. Catalog ingestion requires authoritative source access, appropriate licensing, normalization, validation, and release review.

02Registry record

checked 2026-08-26
Registry status
Beta · catalog on diskParsed catalog: a source-pinned control or requirement catalog for this regime exists in the repo. `catalogPath` is non-null and `controlCount` is real. This does not mean tenant workflows are activated or that an assurance outcome has been earned.
Control units
1,1961,196 OSCAL catalog entries in NIST SP 800-53 Rev. 5, Release 5.2.0: 324 base controls and 872 enhancements; 1,014 active and 182 withdrawn. This is catalog scope, not tenant evidence coverage or onboarding readiness.
Control families
AC · AT · AU · CA · CM · CP · IA · IR · MA · MP · PE · PL · PM · PS · PT · RA · SA · SC · SI · SR
Applies to
federal · critical infrastructure · technology · US · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-26

03Version ledger

3 editions
Rev. 4Superseded2013-04-30
Rev. 5, Release 5.1.1Superseded · supersedes Rev. 4date not published
Rev. 5, Release 5.2.0Current edition · supersedes Rev. 5, Release 5.1.12025-08-27

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to technology · NIST's voluntary, cross-sector reference for governing AI risk, structured as Govern, Map, Measure, and Manage. NIST AI 600-1 is a companion profile for generative AI, not a replacement version or certification.

  2. Same framework family · The outcome-based vocabulary boards use to talk about cyber risk. Not certifiable — it organizes a program rather than testing one.

  3. ASD Essential EightMaturity Model (November 2023)

    Also applies to critical infrastructure · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.

  4. Also applies to technology · The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.

NIST SP 800-53 | ControlFrame